This may sound stupid, but the commonality in all these side channel attacks is that high precision time keeping is a non privileged operation.
Maybe it’s time to make clocks a privileged op as a mitigation. Even making execution time non predictable on untrusted code, such as JavaScript?
If precise time keeping is unavailable these become harder to do.